Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

NetSupport RAT

38
Global rank
48
Month rank
70 infographic chevron week
Week rank
0
IOCs

NetSupport RAT is a malicious adaptation of the legitimate NetSupport Manager, a remote access tool used for IT support, which cybercriminals exploit to gain unauthorized control over systems. It has gained significant traction due to its sophisticated evasion techniques, widespread distribution campaigns, and the challenge it poses to security professionals who must distinguish between legitimate and malicious uses of the underlying software.

RAT
Type
Unknown
Origin
1 September, 2017
First seen
27 August, 2026
Last seen

How to analyze NetSupport RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 September, 2017
First seen
27 August, 2026
Last seen

IOCs

IP addresses
2.16.204.153
2.21.20.144
185.69.122.233
104.18.19.203
150.171.109.104
2.16.168.53
40.126.32.136
2.16.241.217
142.250.154.132
92.223.97.79
150.171.27.11
23.48.23.179
20.190.160.132
23.52.181.141
4.150.223.100
88.221.169.152
142.251.110.101
20.223.35.26
172.211.123.250
48.209.138.168
Hashes
368afeaee4eece34504626d96908481e8f6500d6e3af2ecaab62b9298f9a081a
d96856cd944a9f1587907cacef974c0248b7f4210f1689c1e6bcac5fed289368
c5ec02a9a3c09d1c76bd4086a6112e8a02b44a79ff2a8f28bdd03243dfa06fe9
e0ed36c897eaa5352fab181c20020b60df4c58986193d6aaf5bf3e3ecdc4c05d
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
0cff893b1e7716d09fb74b7a0313b78a09f3f48c586d31fc5f830bd72ce8331f
2cc8ebea55c06981625397b04575ed0eaad9bb9f9dc896355c011a62febe49b5
6562585009f15155eea9a489e474cebc4dd2a01a26d846fdd1b93fdc24b0c269
5dd9f78a898b6d956c245d82a1323d513411fa525edca0c6a30c2c5cff59794e
1be16fe0f1efb26b6da07fbeeb5f887df27433f353dfe7d2cfc3e052e4fcb0bd
5f03cf363d0cc6ea858035722c9ff5ad7290c72695eeb481d01492140011516a
77d9cddcdf03f2e1f02c73df3e6be331435fa58878d9f0e8835b858a1c4cd67a
a29819ae3de2e61e81609066a7dde34dc747a1fec01dd43058f2982aed5c9bc5
c0b31a17e4d06bbb062a2e90170624eab1449e99cf62ca766cb058338f80b058
2afd4f0138b01758678036d0fae8dc4a76402cb3256abdca7e40c23f5a2ba00d
4ffe40321c1a58ac320b2104e7787b161c1197c8fcbe8e7831c5a35cb61b451d
29fc47dccc2c4822192ddec45e5171c0b766c4aa04011970f1ee781876c1ad71
f7bcc59d833c9daa35885156074a65c4f9cb753c6fa101a6c0bbf400e70f8bd7
7e3dfa5df80e568ec663f49b670f36cf13ea973caac8f2e5e6e79b95ddeaf20a
6086d47efab71bf0eb5a861026fb07fd818dbb837225e533fdbafe806405246a
Domains
cdn.create.microsoft.com
ecs.office.com
metadata.templates.cdn.office.net
arkifianetan.one
messaging.engagement.office.com
edge.microsoft.com
go.microsoft.com
slscr.update.microsoft.com
arc.msn.com
self.events.data.microsoft.com
crl.microsoft.com
createcatalog.public.onecdn.static.microsoft
msedge.b.tlu.dl.delivery.mp.microsoft.com
activation-v2.sls.microsoft.com
edge-cloud-resource-static.azureedge.net
google.com
nexusrules.officeapps.live.com
xpaywalletcdn.azureedge.net
ip-api.com
www.bing.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:sa67n75txoxi11guk7al9rp1cpmybpms8xldnp8-kwm&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://nowituandi.com/
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
https://nowituandi.com/favicon.ico
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/web/xlsc.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/manifest/threshold.appcache
https://www.bing.com/dsb/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=us&setlang=en-us&clientdatetime=8%2f27%2f2026%2c%204%3a29%3a57%20am
https://www.bing.com/as/api/windowscortanapane/v2/init
https://www.bing.com/th?id=odswg.5a49ee97-a4ec-4675-94dc-776c5d4b71b9&pid=dsb
https://www.bing.com/rb/1c/cc,nc/8qgg5w3ncsqflirnejktkex2-pa.css?bu=ehmocpqkexmmcnmscq4kexl5uqq7cnl5&or=w
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 3153
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 8509
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 11265
comments 0

What is NetSupport RAT Malware?

NetSupport Manager, developed in 1989, is a legitimate remote administration tool designed for technical support. It enables file transfers, support chat, inventory management, and remote access. It is widely used in corporate environments for employee training and workstation management.

Cybercriminals repurposed it as a Remote Access Trojan RAT, known as NetSupport RAT.

In its malware variant, NetSupport RAT is deployed without consent, often via deceptive methods like fake browser updates, phishing emails, or compromised websites. It uses obfuscated scripts (e.g., JavaScript, PowerShell) to install the NetSupport client (e.g., client32.exe) covertly, establishing persistence through registry keys and connecting to malicious command-and-control (C2) servers. Unlike the legitimate tool, it operates in stealth mode to evade detection.

Since at least 2017, NetSupport RAT has been abused in campaigns, notably surging in 2020 during a COVID-19-themed phishing campaign and continuing into 2025 with sophisticated delivery methods like encrypted .doc files and fake CAPTCHA lures.

Attackers commonly deliver NetSupport RAT through:

  • Phishing emails with malicious links or attachments (e.g., PDFs, LNK files)

  • Malvertising campaigns that redirect to fake update/download pages

  • Compromised websites serving drive-by downloads

  • Trojanized software installers

  • Social engineering ("tech support" scams)

    The malware often employs obfuscation techniques and names its processes to resemble legitimate Windows services.

The Trend of Abusing Legitimate Remote Access Tools

The abuse of legitimate remote access tools is a significant shift in cybercriminal tactics observed since the late 2010s. It has intensified with the rise of remote work, providing attackers with more opportunities to deploy trojanized versions through phishing, drive-by downloads, or compromised websites.

Legitimate tools are less likely to be flagged by antivirus software, as they have valid digital signatures and established reputations. Besides, the network traffic generated by these tools appears normal, making detection through network monitoring more difficult.

This trend extends beyond NetSupport to include other popular remote access solutions like TeamViewer and AnyDesk.

NetSupport RAT Victimology

NetSupport RAT campaigns typically target sectors with valuable data or critical operations:

  • Educational institutions;
  • Healthcare providers;
  • Government agencies;
  • Small and medium businesses (SMBs);
  • Individual users via phishing;

Many attacks begin with phishing emails or malicious ads leading to drive-by downloads, often posing as software updates or urgent security tools. Geographically, attacks are widespread, with notable activity in North America, Europe, and Asia. Both large organizations and small-to-medium enterprises are targeted, as the RAT’s versatility allows attackers to exploit vulnerabilities across diverse environments.

NetSupport RAT Typical Attack Chain

There is a variety of NetSupport RAT samples in ANY.RUN’s Interactive Sandbox detonated and analyzed by over 15,000 SOC teams. Let’s see the malware in action on an example.

View analysis

NetSupport RAT analysis in sandbox NetSupport RAT sample analysis in the Interactive Sandbox

The run begins on the hacked ahaci.com page that shows a fake Cloudflare check. It tells the victim to press Win + R and paste a “verification code”. That text is really a PowerShell one liner. It hides the console with -w h, bypasses the policy with -ep Bypass, creates a GUID file in %TEMP%, downloads yLp.dof from 185.177.239.214 (about 9 MB), and starts a second hidden PowerShell with -f pointing to that script. In the first tracer (PID 4116) you can clearly see Guid::NewGuid(), the curl call, and the follow up execution that hands control to the loader which will fetch and deploy NetSupport RAT.

PowerShell operations deploying NetSupport RAT PowerShell process deploying NetSupport RAT

The second PowerShell process (PID 7384) is the loader for NetSupport RAT components. It calls System.Convert::FromBase64String many times, each time getting back data that starts with MZ, so real PE files. It writes them straight to %APPDATA%\kHLiHMC\ using System.IO.File::WriteAllBytes.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

The names match known NetSupport parts: pcicapi.dll, PCICHEK.DLL, PCICL32.DLL, TCCTL32.DLL, and remcmdstub.exe. Between every write the script sleeps for 108 to 400 milliseconds which looks like an attempt to slow the pattern of API calls.

PowerShell process deploying NetSupport RAT PowerShell process loading NetSupport RAT components

Persistence is created through the registry for the NetSupport client. The script sets HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rMBhIvmVX to C:\Users\admin\AppData\Roaming\kHLiHMC\client32.exe. With this Run key in place, NetSupport RAT will start every time the user logs on.

Registry edit establishing NetSupport RAT persistence Registry edit establishing NetSupport RAT persistence

After the binaries are in place, client32.exe runs (PID 788). It reaches geo.netsupportsoftware.com/location/loca.asp for a quick geo lookup and then sends several small POST requests to 83.222.190.174/fakeurl.htm. From here NetSupport RAT waits for commands from that C2, polling for tasks while staying quiet on the endpoint.

NetSupport RAT network activity on endpoint NetSupport RAT network activity on endpoint

How Does NetSupport RAT Function?

NetSupport RAT operates through a client-server architecture that mirrors its legitimate counterpart. The malicious client component installs on victim systems and establishes communication with attacker-controlled servers. The malware leverages standard networking protocols, often HTTP/HTTPS, to blend with legitimate traffic.

The technical architecture includes several key components: a lightweight client agent that installs on victim systems, command and control servers that receive victim connections and relay attacker commands, and administrative interfaces that provide attackers with user-friendly control panels for managing compromised systems.

Communication protocols employ various obfuscation techniques to evade network-based detection. These may include custom encryption schemes, protocol tunneling, and domain generation algorithms for command and control server locations. The malware also implements sophisticated persistence mechanisms, including Windows service installations, registry modifications, and integration with legitimate system processes.

The modular design allows attackers to deploy additional capabilities as needed, including specialized data harvesting modules, cryptocurrency mining components, and proxy tools for further network exploitation.

What NetSupport RAT Can Do to User Device

Once installed, NetSupport RAT grants attackers extensive control over compromised endpoints. Its capabilities include:

  • Remote Desktop Control: Full access to the victim’s screen for real-time monitoring and manipulation.
  • Data Exfiltration: Ability to capture screenshots, audio, video, and sensitive files.
  • File Management: Uploading and downloading files to introduce additional malware or steal data.
  • System Manipulation: Modifying settings, launching applications, and establishing persistence via registry changes.
  • Surveillance: Keylogging and webcam access to monitor user activity. These features enable attackers to conduct reconnaissance, steal credentials, or move laterally within a network.

How NetSupport RAT Malware Threatens Businesses and Organizations

For businesses and organizations, NetSupport RAT represents a multifaceted threat that extends far beyond individual endpoint compromise. The malware's capabilities enable several high-impact attack scenarios that can severely damage organizational operations and reputation.

  1. Data Breaches and Intellectual Property Theft: Attackers can systematically identify and exfiltrate valuable intellectual property, customer databases, financial records, and strategic planning documents.
  2. Financial Fraud and Business Email Compromise: Attackers can observe legitimate financial transactions, intercept banking credentials, and manipulate payment processes to redirect funds to attacker-controlled accounts.
  3. Ransomware Deployment: The comprehensive system access allows attackers to disable security tools, map network resources, and deploy ransomware across entire organizational networks.
  4. Compliance and Regulatory Impact: Data breaches facilitated by NetSupport RAT can trigger significant regulatory penalties under frameworks like GDPR, HIPAA, and SOX.
  5. Operational Disruption: Even without deploying additional malware, NetSupport RAT can significantly impact business operations through system performance degradation, unauthorized system modifications, and network congestion from data exfiltration activities.

Gathering Threat Intelligence on NetSupport RAT Malware

Threat intelligence plays a critical role in:

  • Identifying new NetSupport RAT campaigns and tactics
  • Sharing Indicators of Compromise (IOCs) across organizations
  • Enabling faster detection and response
  • Providing context on attacker motivations and infrastructures

Start gathering IOCs and behavioral data with the malware name search request to Threat Intelligence Lookup:

threatName:"netsupport"

NetSupport RAT malware samples found via TI Lookup NetSupport RAT malware samples found via TI Lookup

You can also search TI Lookup for samples abusing other Remote Monitoring and Management tools using the rmm-tool tag:

threatName:"rmm-tool"

Malware samples abusing remote access tools found via TI Lookup Malware samples abusing remote access tools

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

NetSupport RAT exemplifies how trusted tools can be subverted for malicious purposes. Its stealth, versatility, and abuse of legitimate software make it a persistent threat to both individuals and organizations.

The trend toward abusing legitimate remote access tools reflects an evolution in cybercriminal tactics and calls for security approaches that go beyond traditional signature-based detection. Organizations must implement comprehensive defense strategies that combine technical controls, user education, and threat intelligence to effectively combat this threat.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

Cephalus screenshot
Cephalus
cephalus
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
Chaos Ransomware screenshot
Chaos ransomware is a malware family known for its destructive capabilities and diverse variants. It first appeared in 2021 as a ransomware builder and later acted as a wiper. Unlike most ransomware strains that encrypt data to extort payment, early Chaos variants permanently corrupted files, while later versions adopted more conventional encryption techniques.
Read More
Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More
BlindEagle screenshot
BlindEagle
blindeagle
BlindEagle is a cyber threat actor primarily associated with espionage and credential theft campaigns targeting organizations in Latin America, especially Colombia. Active since at least 2018, the group relies heavily on phishing, remote access trojans (RATs), PowerShell scripts, and social engineering to infiltrate systems and maintain persistence. BlindEagle is known for continuously evolving its delivery mechanisms and malware stack to bypass detection and compromise high-value targets.
Read More
Oyster screenshot
Oyster
oyster
Oyster (also seen in reporting as Broomstick or CleanUpLoader) is a Windows backdoor/loader actively used in multi-stage intrusion campaigns. Recent campaigns weaponize SEO-poisoning and malvertising to trick IT and dev users into downloading trojanized installers (PuTTY, WinSCP, Microsoft Teams, etc.), which then drop Oyster to establish a persistent foothold and load additional payloads (often leading to data theft or ransomware).
Read More
Crypto malware screenshot
Crypto malware
miner xmrig jsminer
Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.
Read More